CVE-2025-59820

Description

A flaw was found in Krita. This vulnerability allows a heap-based buffer overflow via loading a manipulated TGA (Truevision Graphics Adapter) file.

Statement

A heap-based buffer overflow in Krita, triggered by loading a manipulated TGA file, could lead to arbitrary code execution or application instability. This issue primarily affects the integrity and availability of the Krita application when processing untrusted input.

Understanding the Weakness (CWE)

Other,Integrity,Availability

Technical Impact: Varies by Context; DoS: Resource Consumption (CPU); Modify Memory; Read Memory

When the quantity is not properly validated, then attackers can specify malicious quantities to cause excessive resource allocation, trigger unexpected failures, enable buffer overflows, etc.

Frequently Asked Questions

Want to get errata notifications? Sign up here.